Sws develops a narrow product portfolio centered on simple web-server and website-software offerings that achieve prominence despite modest disclosure volume, likely reflecting the widespread deployment of lightweight web-serving components. The vendor's vulnerabilities characteristically involve issues classified as miscellaneous or placeholder categories in NVD taxonomy, a pattern that may reflect either diverse or inadequately characterized weakness types across the product line. Specific severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sws over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-1864MEDIUM Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitrary files via a ".." (dot dot) in an HTTP request. | Dec 31, 2002 | 5.0 | 36 | NO | YES |
CVE-2002-2370MEDIUM SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request that does not end with a newline. | Dec 31, 2002 | 5.0 | 28 | NO | YES |
CVE-2002-1870HIGH Simple Web Server (SWS) 0.0.4 through 0.1.0 does not properly handle when the recv function call fails, which may allow remote attackers to overwrite program data or perform action | Dec 31, 2002 | 7.5 | 25 | NO | NO |
CVE-2006-5636MEDIUM PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDI | Nov 1, 2006 | 5.1 | 23 | NO | YES |
CVE-2006-2114HIGH Buffer overflow in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via a long request. | May 1, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-2115HIGH Format string vulnerability in SWS web Server 0.1.7 allows remote attackers to execute arbitrary code via unspecified vectors that are not properly handled in a syslog function cal | May 1, 2006 | 7.5 | 20 | NO | NO |
CVE-2002-1866MEDIUM Simple Web Server (SWS) 0.0.4 through 0.1.0 does not close file descriptors for 404 error messages, which could allow remote attackers to cause a denial of service (file descriptor | Dec 31, 2002 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sws.
Media articles that mention a CVE ID that affects a product developed by Sws — matched by CVE ID, not by vendor name.